Privacy

Privacy policy.

Last updated: 12 September 2026

This policy explains what personal information Empower Her Thrive collects, why, and what we do with it. It covers the newsletter, the contact form, the director-readiness scorecard, and booking a call. We only collect what a small coaching practice needs to reply to you and run its services.

Who we are

Empower Her Thrive is a solo leadership coaching practice for women leaders. It is operated by Marerisoft, MB, which is the data controller for the information described here.

If you have a question about your data, or want to exercise any of the rights below, email hello@empowerherthrive.com.

What we collect, and why

We collect information only when you choose to give it, through one of five things.

Newsletter

If you subscribe, we store your email address. Subscription is double opt-in: after you sign up we email you a confirmation link, and nothing is added to the mailing list until you click it. Every newsletter carries a one-click unsubscribe link, and unsubscribing removes you from the list.

Contact form

When you send a message, we store your name, email address, and the message itself, so the coach can read it and reply. Your email is used as the reply address.

Director-readiness scorecard

The scorecard asks for your first name and email address before it begins. We store them from that moment, whether or not you finish, so we can send your results and, where relevant, follow up about coaching; when you complete it, we store your scores alongside them.

Booking a call

When you book a call, we store your name, email address, your current role, any notes you add, and the time you chose. To place the call in a calendar and create a video link, your name, email, role and notes go into the calendar entry, which both of us can see (see below). If you chose to attach your scorecard result to the booking, it is stored with the booking and shown to the coach; it is not written into the calendar entry.

Booking waitlist

If no times are open and you leave your name, we store your name and email address so we can tell you when times open again. It is one email, sent the morning after times reopen, and you are not added to the newsletter.

Where your data goes

We use a small set of established service providers to run the site and its services. We do not add others without reason.

  • Supabase stores newsletter subscriptions, contact messages, scorecard registrations and results, and bookings in a secure database.
  • Resend sends the emails: newsletter confirmations and issues, contact notifications, scorecard results and their one follow-up, booking confirmations, the reminder the day before a call, a short note the morning after it, and waitlist notices. Confirmed subscribers are also held in Resend so the newsletter can be sent.
  • Google Calendar receives your name and email as attendee details when you book a call, plus your current role and any notes you added, written into the calendar entry so the coach can prepare. Your scorecard result is not put there. This is what creates the calendar entry and its video meeting link.
  • Vercel hosts the website and runs the code that handles the forms.

What we don’t do

  • We do not sell or rent your data to anyone.
  • We do not use advertising or cross-site tracking.
  • The site sets no cookies. It does keep a few things in your own browser so the pages work: your scorecard answers and progress, the time zone you picked on the booking page, and whether you dismissed a banner. That stays on your device, is never sent anywhere, and clearing your browser data removes it.
  • We do not use analytics that can identify you. Vercel Web Analytics counts page visits without cookies, and since September 2026 it also counts a few anonymous actions so we can see where the site is confusing — that a scorecard was started or finished, that a booking or an enquiry was sent, that an FAQ was opened, that a post was read. Those counts record what happened and nothing about who did it: no name, no email, no address, nothing you typed. There is no profile behind them, and no way to work back from a count to a person.
  • Forms carry automated anti-spam checks. To rate-limit abuse we store a one-way hash of the sending address or IP, never the address or IP itself, and contact messages keep a hashed IP alongside them. These protect the forms; they are not used to profile you.

Our legal bases

We process your data under the EU General Data Protection Regulation (GDPR) and Lithuania’s Law on Legal Protection of Personal Data, relying on the following legal bases.

  • Consent for the newsletter. You opt in, confirm by email, and can withdraw at any time by unsubscribing.
  • Legitimate interests for replying to enquiries, handling bookings, sending scorecard results you asked for, and running anti-spam checks. This lets a small practice respond to the people who contact it and keep its forms working, in a way you would reasonably expect.

How long we keep your data

  • Newsletter subscribers: if you unsubscribe, we keep a record that you did, so we do not email you again by mistake. Ask us and we will remove it entirely.
  • Contact messages, scorecard results, bookings, and waitlist entries: kept as ordinary business records until you ask us to delete them.

You can ask us to delete your data at any time (see your rights, below).

Your rights

Under the GDPR you have the right to:

  • ask for a copy of the data we hold about you (access);
  • ask us to correct data that is wrong or incomplete (rectification);
  • ask us to delete your data (erasure);
  • ask us to limit how we use your data while a concern is looked into (restriction);
  • receive your data in a portable format (portability);
  • object to processing we base on legitimate interests;
  • withdraw your consent to marketing at any time.

How to exercise your rights

Email hello@empowerherthrive.com and tell us what you would like. We will respond within one month, and there is no charge for a reasonable request.

International transfers

Our database, and the code that handles the forms, run in London. The European Commission recognises the United Kingdom as protecting personal data to the EU standard, under an adequacy decision renewed in December 2025.

Some of our service providers are US companies and may process data in the United States. Those transfers rely on the EU–US Data Privacy Framework where the provider is certified under it, and otherwise on the European Commission’s standard contractual clauses.

Complaints

If you are unhappy with how we handle your data, please tell us first, so we have the chance to put it right. You also have the right to complain to a data protection authority. Ours is Lithuania’s State Data Protection Inspectorate, at vdai.lrv.lt, which takes complaints in Lithuanian. If you live or work in another EU country, you can complain to the authority there instead.

Changes to this policy

If we change how we handle data, we will update this page and the date at the top. We will tell newsletter subscribers by email about significant changes that affect them.